PkgRadar

npm · registry.npmjs.org

@foodmarketmaker/ckeditor-build

Remote Dependency Spec: dependencies.@jsdevtools/npm-publish="github:JS-DevTools/npm-publish"

Why PkgRadar flagged 16.0.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@jsdevtools/npm-publish="github:JS-DevTools/npm-publish" · package.json
mediumNew Remote Dependency Vs Previousdependencies.@jsdevtools/npm-publish added in 16.0.0 vs 1.2.0: "github:JS-DevTools/npm-publish" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
16.0.0Review242026-06-03
1.2.0Low risk02026-06-01

Block this in CI

PkgRadar gates @foodmarketmaker/ckeditor-build (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @foodmarketmaker/[email protected]
@foodmarketmaker/ckeditor-build — npm security scan | PkgRadar